Security & Compliance
Six controls a CISO signs off on. Before pilot.
AscendCore was architected for CISOs and CIOs, not just help-desk managers. Every action is gated by a named-admin approval, every credential lives in its own logical vault, and every execution appends to a SHA-256 audit chain.
100%
Actions require a named-admin approval. No exceptions, no autopilot mode.
Architecture ledger
06 controls
Logical vault, per org
Per-Organization Isolation
Named-admin gate · 100% HITL
Approval-First Execution
SHA-256 hash chain · Postgres
Tamper-Evident Audit Chain
HMAC-SHA256 · JWT
Verified Webhook Integrity
Server-enforced · OIDC SSO
RBAC + SSO
TLS 1.3 · AES-256
Encryption In Transit & At Rest
The proof
One chain. Every decision. Provable.
Every approve, deny, and execution appends to a tamper-evident SHA-256 chain backed by Postgres. Each record's hash includes the prior record's hash. Export it as CSV, re-hash it from genesis, and check it offline. The proof is the customer's, not ours.
SOC 2 Type I is planned. This export is evidence you can hand an auditor, not a compliance certification.
GOVERNANCE · AUDIT CHAIN
✓ chain re-computed from genesis. every value matched.
simulated preview, real grammar · the live chain is verifiable in the demo
Security posture · Verifiable
Verifiable today. Roadmap disclosed.
The controls a CISO will ask about, split honestly: what's enforced in production right now, and what's on the audit calendar.
Live in production today
Logical vault, per org
Per-Organization Isolation
Each org's integration secrets (Okta, Entra, M365, Slack) are scoped to that org and managed in Doppler. Credentials resolve only for that org's traffic, namespaced across the audit chain and operational store.
Named-admin gate · 100% HITL
Approval-First Execution
Every runbook stops at an explicit human sign-off before it touches production. No autonomous actions. Idempotent retries prevent double-execution under network failure or a double-tap.
SHA-256 hash chain · Postgres
Tamper-Evident Audit Chain
Every approve, deny, and execution appends to a Postgres-backed SHA-256 hash chain. Each row links to the prior row's hash, so a single altered row breaks verification. Customer-exportable for independent proof.
Export the audit chainHMAC-SHA256 · JWT
Verified Webhook Integrity
Inbound Slack requests are verified via HMAC-SHA256 with timing-safe comparison; inbound Teams activities via JWT against Microsoft's public JWKS. Spoofed requests are rejected at the edge.
Server-enforced · OIDC SSO
RBAC + SSO
Owner / Demo / Guest roles enforced server-side on every mutation. OIDC SSO for admin login (Microsoft Entra + Okta), with optional mandatory-SSO so your IdP brokers MFA and conditional access.
TLS 1.3 · AES-256
Encryption In Transit & At Rest
TLS 1.3 in transit at the Netlify edge; AES-256 at rest for all stored data (Cloudflare R2, Netlify Blobs, Neon). No plaintext secrets on disk or in logs.
On the roadmap
SOC-2 Type I
~90-day windowVanta enrollment planned (begins once budgeted); a ~90-day audit window then certification. The underlying controls, data-retention, and incident-response policies are already live and enforced today.
Independent penetration test
Q3 2026Third-party assessment ahead of first enterprise deployments. Reports available under NDA for active procurement.
SOC-2 Type II
H2 2027Follows Type I plus an observation period.
ISO 27001
2027Post-SOC-2 alignment for international procurement. Not yet mapped or certified.
Customer-managed keys (BYOK)
H1 2027Bring-your-own-KMS for application-level data encryption.
Security cleared? See what a pilot looks like.
Items move from roadmap to live via dated commits and changelog entries. For status against a specific control, email security@ascendcore.ai.
Sub-processors
The third-party services that may process customer data while delivering AscendCore. Updated whenever we add or remove a vendor; see the timestamp at the top of this page.
| Vendor | Purpose | Region | Terms |
|---|---|---|---|
| Anthropic | LLM inference (intent classification) | US | No training on API data per Anthropic terms |
| Slack Technologies | Bot framework + slash commands | US | Standard Slack DPA |
| Microsoft (Bot FW, Graph, Entra) | Teams bot, Microsoft 365 / Entra automations | US/EU | Microsoft DPA + EU SCCs |
| Cloudflare R2 | Object storage at rest (AES-256) | US | Cloudflare DPA |
| Netlify | Application hosting + edge functions + Blobs | US | Netlify DPA |
| Neon | Postgres database for tamper-evident audit chain | US | Neon DPA · US East 2 region |
| Doppler | Secret management with auditable secret access | US | Doppler DPA |
| Resend | Transactional email (notifications) | US | Resend DPA |
| PostHog | Product analytics (anonymized after consent) | US/EU | PostHog DPA · cookie-consent gated |
| Vanta | Compliance automation (after enrollment) | US | Vanta DPA · enrollment planned (begins once budgeted) |
Questions we get from security teams.
Honest answers, including for the things we're still building.
Want to verify any specific control?
We'll do a technical review call, walk through architecture in detail, share our internal audit findings under NDA, or answer specific items on your enterprise security questionnaire.
Ready to take L1 off your queue?
AscendCore is onboarding private-beta pilots now. Onboarding takes days, not months, with human-in-the-loop approval on every action.
No credit card required. 30-day pilot. Cancel anytime.
